Matt Seeds

Managing Director

MATT SEEDS

I was watching the footy on Saturday when a key defender misjudged where his opponent was running, half a second too slow to react, and the ball sailed through for a goal. Eighteen players on the field, and one wrong read undid the lot. 

Monday morning, something almost identical happened in an office here in Perth. One of the staff opened an email that looked close enough to real, a supplier’s logo, an overdue invoice, and clicked 

One wrong read. That’s all it took to undo the rest of the team’s work. 

Your team is your biggest security risk, and your strongest defence. Cyber security awareness training is the difference. 

What is cyber security awareness training? 

Here’s my take. Cyber security awareness training teaches your staff how to spot and respond to the threats that get through, phishing emails, social engineering, the fake invoice that looks a little too convincing. Get it right, and your team catches the mistake before it costs you anything. 

I’ve sat across the table from enough Perth business owners to know where the gap sits. It’s rarely the firewall.  

It’s the moment an office manager’s flat out, three tabs side-by-side on the screen, and an email lands that reads close enough to real to open without a second look. Your business doesn’t need enterprise scale to be a target, it needs one wrong read on a busy Tuesday. 

Is my business too small for this to matter? 

No. If anything, smaller businesses get targeted harder, because attackers know the defensive structure usually isn’t built yet. 

I hear this one a lot, usually from a business owner who assumes size buys safety. It doesn’t 

A construction firm with thirty staff or a professional services practice with fifteen is often an easier mark than a listed company, not because the people are careless, but because the controls that would normally catch a mistake haven’t been drilled in.  

Being smaller doesn’t take you off the field, it just means fewer players are covering the same ground. 

What should a cyber security awareness programme cover? 

A practical programme covers phishing recognition, password hygiene, safe use of business devices, and a clear process for reporting something that feels off, delivered in a way your team will remember, not just recall in the annual quiz. 

Good training doesn’t look like a once-a-year video that gets played in the lunchroom and never mentioned again. It looks like short, regular sessions your team can absorb without losing half a day.  

Think of these as the training track work, not matchday itself, the reps that make the read possible later. The thing I see missed isn’t the phishing test, it’s the follow-up.  

You run one session, tick the box, and it’s forgotten by the time it matters. Training that sticks needs repetition, the same way a defensive read-only becomes instinct after enough practice, not after one walkthrough. 

What should I include in my team’s cyber security training? 

Cover phishing recognition, password and MFA basics, safe use of devices and email, a clear reporting process, and how to handle unusual requests like invoice or transfer changes. Between them, they cover what gets exploited. 

The Starting Line-Up 

  1. Spot phishing by the mismatched sender, urgent tone, or almost-right logo. 
  2. Never share passwords and turn on MFA to catch what passwords miss. 
  3. Only click, download, or forward what you know is safe. 
  4. Report anything that looks wrong straight away. 
  5. Double-check unusual requests, like a sudden invoice change or urgent transfer. 

Explore our cyber security services for how this fits into a broader security approach.

How do I get my team started with cyber security training? 

A practical starting point is a baseline assessment of where your team’s gaps sit, followed by training that fits how your business already runs, not a generic programme that gets ignored after week one. 

You don’t need a full pre-season to start. You need one training session, this week. I ran something similar for the Wheatbelt Business Network a while back. 

Pick Two, Not Twenty 

The Wheatbelt Business Network wanted their members trained on cyber security, but with no in-house IT expertise to draw on, a full curriculum would have lost them by the second slide. The fix was to pick two things likely to catch a member out, phishing and invoice fraud, and build a session entirely around real examples of each rather than a general overview. 

The model’s worth copying. Pick what’s most likely to hit your business specifically, not what looks good on a checklist, and start there.

How often should I be running this for my team? 

At minimum, annually. But teams that run shorter sessions quarterly, or even monthly, hold their structure far better than teams that train once and stop. 

Treat it like fitness, not a certificate. A defensive line that skips its training track between games loses its read by round three, and your team is no different.  

October is Cyber Security Awareness Month in Australia, a natural annual anchor point, but the teams I see holding their line are the ones training more often than that. Read more in our case studies to see how this has played out for other Perth businesses, including in professional services. 

Where to start 

That defender on Saturday got it wrong, and it cost his team the game. Training is what closes that gap, for him and for your team. One wrong read doesn’t have to be the difference between a close call and a costly problem, provided the training’s there before it’s needed. 

If you’re not sure where your team’s gaps sit, a conversation with the cyber security team costs nothing and gives you a clear picture of where to start. 

 

Managing Director

MATT SEEDS

Matt founded Inspired IT after years working inside MSPs, where he saw the opportunity created by modern cloud technologies and the need for a better kind of IT partner.